diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 57c8a6bed..d70d30c0a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -152,9 +152,9 @@ jobs: - name: Run npm audit working-directory: frontend run: | - # Only fail on fixable high/critical vulnerabilities. - # Unfixable issues (e.g. npm's bundled tar) are tracked via security.yml. - npm audit --json > /tmp/audit.json 2>/dev/null || true + # Only audit production dependencies — dev dependency vulnerabilities + # don't affect end users. Detailed audits are handled by security.yml. + npm audit --omit=dev --json > /tmp/audit.json 2>/dev/null || true python3 -c " import json, sys data = json.load(open('/tmp/audit.json'))